CVE-2024-27264: IBM Performance Tools for i privilege escalation
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 284563.
Other sources
IBM Performance Tools for i could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27264?
CVE-2024-27264 has a critical severity rating due to the potential for local users to gain elevated privileges.
How do I fix CVE-2024-27264?
To fix CVE-2024-27264, update the IBM Performance Tools for i to the latest version provided by IBM.
Who is affected by CVE-2024-27264?
CVE-2024-27264 affects local users on IBM Performance Tools for i versions 7.2 through 7.5.
What can an attacker do with CVE-2024-27264?
An attacker exploiting CVE-2024-27264 could execute user-controlled code with administrator privileges.
Does CVE-2024-27264 require user interaction to exploit?
CVE-2024-27264 can be exploited by a local user without requiring additional user interaction.